0% found this document useful (0 votes)
2 views6 pages

Security and Cyber Laws Assignment

The document discusses various aspects of digital security, including the three pillars of digital security: confidentiality, integrity, and availability. It covers different types of cyber threats such as DDoS attacks, malware, and phishing, as well as legal frameworks like the Information Technology Act and UNCITRAL model law. Additionally, it explains concepts related to cryptography, cyber forensics, and intellectual property rights, emphasizing the need for regulation in cyberspace.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views6 pages

Security and Cyber Laws Assignment

The document discusses various aspects of digital security, including the three pillars of digital security: confidentiality, integrity, and availability. It covers different types of cyber threats such as DDoS attacks, malware, and phishing, as well as legal frameworks like the Information Technology Act and UNCITRAL model law. Additionally, it explains concepts related to cryptography, cyber forensics, and intellectual property rights, emphasizing the need for regulation in cyberspace.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Assignment

Name: Niamatullah Khudayar Date:11/26/2024


Subject: MCS-215: Security and Cyber Laws

Q1:
A) What are the three pillars of digital security? What is the need for digital security?
The three pillars of digital security are:
[Link]: Ensuring that sensitive information is accessed only by authorized users.
[Link]: Maintaining the accuracy and completeness of data, preventing unauthorized alterations.
3. Availability: Ensuring that information and resources are accessible to authorized users when needed.
The need for digital security arises from the increasing reliance on digital systems and networks, which are
vulnerable to attacks that can lead to data breaches, loss of sensitive information, and significant financial
and reputational damage.

B) Explain the following in the context of security issues/attacks:


(I) DDoS attacks: Distributed Denial of Service (DDoS) attacks involve overwhelming a target system,
server, or network with a flood of internet traffic, rendering it unavailable to users.
(II) Malware: Malicious software designed to harm, exploit, or otherwise compromise computer systems,
including viruses, worms, and ransomware.
(III) Crypto-jacking: The unauthorized use of someone else's computer to mine cryptocurrency, often
without the user's knowledge, which can slow down their device and increase energy costs.

C) Explain the term Cyber Security intrusion detection with the help of an example.
Cyber Security intrusion detection refers to the monitoring of systems and networks for malicious activities
or policy violations. For example, an Intrusion Detection System (IDS) may analyze network traffic patterns
to identify unusual behavior, such as a sudden spike in data being sent to an external server, which could
indicate a data breach.

D) What are the laws related to unauthorized access and web jacking?
Section 65 and Section 66 prescribes imprisonment and fine for unauthorized access and knowingly or
intentionally conceal destroy or alter computer source code which generally happens during defacement of
website.
Q2: Explain the following terms with the help of an example of each.
A) Function-based substitution cipher: A method of encryption where each letter is replaced by another
letter based on a fixed system. For example, in a simple Caesar cipher with a shift of 3, 'A' becomes 'D', 'B'
becomes 'E', etc.
B) Five Key Functions of Cryptography:
1. Confidentiality: Ensures that information is not disclosed to unauthorized users.
2. Integrity: Verifies that the information has not been altered during transmission.
3. Authentication: Confirms the identity of the parties involved in communication.
4. Non-repudiation: Prevents an entity from denying the authenticity of their signature on a message.
5. Key exchange: The approach by which crypto keys are shared between sender and receiver.

C) Steganography: The practice of hiding a message within another medium, such as embedding a text
message within an image file. For instance, a digital image could contain hidden text that is not visible to
the naked eye.

D) RSA algorithm: A widely used public-key cryptographic system that relies on the mathematical difficulty
of factoring large prime numbers. For example, if Alice wants to send a secure message to Bob, she would
encrypt it with Bob's public key, which only Bob can decrypt with his private key.

E) Hash functions: Algorithms that convert input data of any size into a fixed-size string of characters,
which is typically a hash code. An example is SHA-256, used in various security applications and protocols,
including SSL and blockchain.

F) Pseudo-random number generator: An algorithm that generates a sequence of numbers that approximates
the properties of random numbers. For instance, the Linear Congruential Generator (LCG) is a simple
method for producing a sequence of pseudo-random numbers.
Q3:
A) List practices for implementing the CIA triad in data security.
1. Data Encryption: To ensure confidentiality.
2. Access Control Policies: To maintain integrity by restricting access.
3. Regular Backups: To ensure availability in case of data loss.

B) Explain the following:


(I) Phishing attacks: Attempts to trick individuals into revealing sensitive information by masquerading as
trustworthy entities through emails or websites.
(II) Ransomware attacks: Malicious software that encrypts a victim's files and demands payment for the
decryption key.
(III) **State-sponsored attacks: Cyber-attacks that are conducted by government entities against other
nations or organizations for espionage or sabotage purposes.

C) Explain the six principles of security management.


1. Availability: Ensuring that authorized users have access to information when needed.
2. Integrity: Ensuring data is accurate and trustworthy.
3. Confidentiality: Protecting sensitive information from unauthorized access.
4. Accountability- Accountability incorporates the procedures, policies and controls essential to follow
activities to their source.
5. Assurance- Assurance addresses the procedures, strategies and controls which are used to create certainty
that specialized and equipped security measures are working as anticipated.
6. Privacy- It centers on the constitutional rights of people, the motivation behind data assortment and
processing, security predilection and the manner in which organizations administer individual’s data.

D) Explain the terms:


(I) Security audit: A systematic evaluation of the security of a company's information system by measuring
how well it conforms to a set of established criteria.
(II) Security and usability: The balance between protecting data and ensuring that systems remain user-
friendly. Overly complex security measures can hinder usability.
Q4:
A) Why is there a need to regulate cyberspace? Explain, giving reasons.
Regulating cyberspace is necessary to protect users from cyber threats, ensure the privacy of personal data,
and promote lawful behavior online. It also helps to prevent cybercrimes, such as fraud and identity theft,
and maintains public trust in digital systems.

B) Explain the role of filtering devices and rating scales in regulating Internet content.
Filtering devices help to block access to inappropriate or harmful content based on predefined criteria, while
rating scales categorize content to inform users about its suitability. Together, they aid in protecting minors
from harmful materials and ensuring a safe online environment.

C) What is the UNCITRAL model law? Explain its doctrines and parts.
The UNCITRAL (United Nations Commission on International Trade Law) model law provides a legal
framework for international commercial transactions and aims to harmonize laws across jurisdictions. Its
doctrines include provisions on electronic contracts, electronic signatures, and the validity of electronic
records.

D) What are the international initiatives for the regulation of cyberspace?


International initiatives include agreements like the Budapest Convention on Cybercrime, which aims to
promote international cooperation in combating cybercrime, and the UN's efforts to develop global norms
for responsible state behavior in cyberspace.
Q5:

A) Explain the classification of cybercrimes with the help of examples.


1. Personal Cybercrimes: Identity theft, where personal information is stolen for fraudulent purposes.
2. Property Cybercrimes: Hacking into systems to steal sensitive data or intellectual property.
3. Cyberbullying: Harassment or intimidation of individuals online.

B) How is Computer Contaminant defined under Section 43 of the Information Technology Act 2000?
A Computer Contaminant is defined as any set of instructions that can alter, damage, or destroy data or
programs residing in a computer resource.

C) List any six offences, as per the Information Technology Act, 2000.
1. Hacking (Section 66)
2. Identity theft (Section 66C)
3. Data theft (Section 43)
4. Cyber terrorism (Section 66F)
5. Publishing obscene material (Section 67)
6. Violation of privacy (Section 66E)

D) What are the Liabilities of network service providers? Explain.


Network service providers are liable for any unlawful content hosted on their platforms if they fail to act
upon receiving knowledge of the content. They must also implement reasonable security practices to protect
user data.

E) Explain the term cyber forensics.


Cyber forensics is the field of forensic science that focuses on the recovery and investigation of material
found in digital devices, often in relation to computer crime. It involves collecting, preserving, and
analyzing electronic data to be used in legal proceedings.
Q6:
A) Explain the following forms of IPR and related regulatory framework:
(I) Copyrights and related rights: Protect the expression of ideas through artistic works and provide creators
with exclusive rights to use and distribute their work.
(II) Patents: Protect inventions by granting exclusive rights to the inventor for a certain period, preventing
others from using, making, or selling the invention without permission.
(III) Trademarks: Protect symbols, names, and slogans used to identify goods or services, preventing
confusion among consumers.

B) What is meant by the terms - linking, in-lining, and framing in the context of IPR?
Linking: Refers to creating a hyperlink to another website or page.
In-lining: Involves embedding content from one site into another, often without permission.
Framing: Displays content from another site within a frame of the linking site, potentially misleading users
about the source of the content.

C) What are domain name disputes? Explain with the help of an example.
Domain name disputes arise when two parties claim rights to the same domain name. For example, if a
company named "Tech Innovations" finds that a competitor has registered the domain
"[Link]," they may file a dispute to reclaim it based on trademark rights.

You might also like